CVE-2022-0918

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/03/2022
Last modified:
03/11/2025

Description

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:port389:389-ds-base:1.4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*